Privacy Policy
We take the protection of your personal data seriously and treat it confidentially in accordance with the General Data Protection Regulation (GDPR / Regulation (EU) 2016/679) and the Spanish data protection act (Ley Orgánica 3/2018, LOPDGDD). The controller is established in Spain; the supervisory authority is the Spanish Data Protection Agency (AEPD).
1. Controller
Dr. Janosch Leugner
AddressAvenida Litoral de Agache 38
38591 La Puente
Teneriffa, España
Phone Email2. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and to withdraw consent given (Art. 7(3) GDPR). An informal message to the contact details above is sufficient.
3. Right to lodge a complaint
The competent supervisory authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. You may also contact the authority of your place of residence.
4. Hosting and transfer to a third country (USA)
This website is operated with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (an EU-based processor; data processing agreement under Art. 28 GDPR). Server location: a data centre in Ashburn, Virginia, USA → processing in a third country. The transfer is safeguarded by EU Standard Contractual Clauses (Art. 46 GDPR) and technical measures (TLS). The USA does not offer a fully equivalent level of data protection; access by US authorities cannot be entirely ruled out. Legal basis: Art. 6(1)(f) in conjunction with Art. 46(2)(c) GDPR.
5. Server log files
On each access the following are automatically collected: shortened IP address, date/time, requested resource, HTTP status, data volume, referrer, browser/operating system. Purpose: technical provision and security (Art. 6(1)(f) GDPR). Deleted after 14 days at the latest.
6. SSL/TLS encryption
The website uses SSL/TLS encryption throughout (“https://”).
7. Contact form
When you contact us we process your name, email, area of interest (optional) and your message in order to handle your enquiry (Art. 6(1)(b) or (f) GDPR). A honeypot field and rate limiting are used for spam protection. Stored until the purpose no longer applies or you request deletion.
8. Fonts (self-hosted)
Fonts are served locally from our server. There is no connection to Google Fonts; your IP is not transmitted to third parties for this purpose.
9. Cookies
This website sets no cookies for analytics or marketing and integrates no tracking services. Only in the members area, after login, a technically necessary session cookie is set to keep you logged in during your session (Art. 6(1)(b) or (f) GDPR); it contains no tracking function and is deleted on logout or when the session expires.
10. Appointment booking (Calendly)
If you actively use a booking link, you are redirected to Calendly (Calendly LLC, USA); data may be transferred to the USA. The basis is your consent (Art. 6(1)(a), Art. 49(1)(a) GDPR).
11. Members area / user account
If you create a user account for the protected members area, we process the data you provide (name, email address, password) as well as your progress in the guides, the content of your personal coaching journal and the details recorded in the application tracker (company, role, notes, status, follow-up dates). Journal and application content is stored encrypted (AES-256-GCM) and is visible only to you; it is deleted automatically when you delete your account. The password is stored exclusively as a cryptographic hash (bcrypt) — never in plain text. Further personal account data is additionally stored encrypted on the server (AES-256-GCM). A technically necessary session cookie is set to keep you logged in; forms in the members area are protected by a CSRF token. The legal basis is the performance of the usage relationship (Art. 6(1)(b) GDPR) and our legitimate interest in secure operation (Art. 6(1)(f) GDPR). You may have your account and all associated data deleted at any time (Art. 17 GDPR) — an informal message to the contact details above is sufficient. Via "Settings → My data" you can also export your data at any time as a machine-readable file (right to data portability, Art. 20 GDPR).
12. Newsletter and promotional emails
If you explicitly consent via a form (e.g. the AVGS check), we store your email address (encrypted, AES-256-GCM) in order to send you news, tips and offers by email. Consent is optional and independent of other functions (such as sending a letter). We use a double opt-in procedure: you first receive a confirmation email, and we only send newsletters after you confirm. Your consent is documented with timestamp and wording. The legal basis is your consent (Art. 6(1)(a) GDPR in conjunction with § 7 UWG). You can withdraw your consent at any time with future effect — via the unsubscribe link in every email or by message to the contact details above; we then remove your address from the distribution list.
13. Status
As of June 2026. We update this policy as needed.